Mypro
Vendor:
First CVE: Oct 6, 2017 · Active for 8 years
28
Total CVEs
More Total CVEs than 96% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mypro over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2017
8 years ago
Most Recent CVE
Jun 11, 2025
408 days ago
CVE Severity & Scoring
Mypro28 CVEs
11%
50%
39%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (7.1%)
Network26 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None27 (96.4%)
Unknown0 (0.0%)
Required1 (3.6%)
Privileges Required
Low9 (32.1%)
High0 (0.0%)
None19 (67.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28384HIGH mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | Apr 27, 2023 | 8.8 | 61 | NO | YES |
CVE-2022-2234HIGH An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. | Aug 24, 2022 | 8.8 | 52 | NO | NO |
CVE-2018-11311CRITICAL A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files | May 20, 2018 | 9.1 | 48 | NO | YES |
CVE-2025-24865CRITICAL The administrative web interface of
mySCADA myPRO Manager
can be accessed without authentication
which could allow an unauthorized attacker to retrieve sensitive
information an | Feb 13, 2025 | 9.8 | 45 | NO | YES |
CVE-2023-28400HIGH mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | Apr 27, 2023 | 8.8 | 37 | NO | NO |
CVE-2025-22896HIGH mySCADA myPRO Manager
stores credentials in cleartext, which could allow an attacker to obtain sensitive information. | Feb 13, 2025 | 7.5 | 34 | NO | YES |
CVE-2024-4708CRITICAL mySCADA myPRO
uses a hard-coded password which could allow an attacker to remotely execute code on the affected device. | Jul 2, 2024 | 9.8 | 31 | NO | NO |
CVE-2025-25067CRITICAL mySCADA myPRO Manager
is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands. | Feb 13, 2025 | 9.8 | 30 | NO | NO |
CVE-2021-44453CRITICAL mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands. | Dec 23, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-43985CRITICAL An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization. | Dec 23, 2021 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
10.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Mypro
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 2 | 7.2 | 9.0% | 0 | 1 |